#1General purpose tools for collecting various types of information about targets.
Kitploit recommended

Opinionated organisation-centric OSINT footprinting inspired from recon-ng and Maltego
An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

A small python script to check for Cross-Site Tracing (XST)

Latency x-ray for undocumented hardware

Documents and identifies 2,953 Chrome extensions silently probed by LinkedIn, providing tools to fetch extension names and analyze browser…

Automatic Service Enumeration Script

CVE-2019-5418 - File Content Disclosure on Ruby on Rails

Semi-automated penetration testing framework with TUI, integrating Nmap, OpenVAS, Metasploit, and Faraday for streamlined information gathering,…

Automated tool that hunts for world-readable passwords in Active Directory LDAP databases by leveraging Kerberos authentication and ldapsearch to…

Curated collection of threat hunting and detection queries for CrowdStrike Falcon (CQL) and Microsoft Defender XDR (KQL), mapped to MITRE ATT&CK…

A security testing Slackbot built with a Kubernetes backend on the Google Cloud Platform

Passive DNS server that detects exposed cloud storage buckets (AWS S3, GCP, Azure) by resolving DNS requests, tracing CNAME chains, and flagging…

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

Tool that monitors, analyzes and limits the bandwidth of devices on the local network without administrative access (for Windows only)

Pentesters spend too much time during information gathering phase. Flashlight (Fener) provides services to scan network/ports and gather information…

A wrapper for Nmap to quickly run network scans

PatrowlHears - Vulnerability Intelligence Center / Exploits

Cisco Exploit (CVE-2019-1821 Cisco Prime Infrastructure Remote Code Execution/CVE-2019-1653/Cisco SNMP RCE/Dump Cisco RV320 Password)